๐ฉ๐ช
excill
2026-06-16 03:01:21
(1 week ago)
Honeypot mesh observed 7239 attack events in 24h โ cowrie/dionaea/heralding/suricata
Port Scan
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-15 17:33:22
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.101.249.171 (171.249.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.101.249.171 (171.249.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 13:33:18.879438 2026] [security2:error] [pid 9375:tid 9375] [client 34.101.249.171:42844] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ohnosound.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ohnosound.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ajA3XljwZBxpoPQSK9F_gAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 08:30:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.249.171 (171.249.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.249.171 (171.249.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 04:30:34.477657 2026] [security2:error] [pid 26158:tid 26158] [client 34.101.249.171:40590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jensen.silsby.com"] [uri "/.env.development"] [unique_id "ai-4KsGj4bVzDwsbXHHZfQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 06:22:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.249.171 (171.249.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.249.171 (171.249.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 02:21:58.645163 2026] [security2:error] [pid 1950:tid 1950] [client 34.101.249.171:60104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theseoscribe.com"] [uri "/api/v2/.env"] [unique_id "ai-aBhcPX1oEvWeH-E869gAAAHc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-06-15 05:24:36
(2 weeks ago)
Aggressive web search of vulnerable pages: /.env.local /backend/.env.local /test/.env /backend/api/. ...
show more
Aggressive web search of vulnerable pages: /.env.local /backend/.env.local /test/.env /backend/api/.env /app/api/.env ...
show less
Web App Attack
๐ซ๐ฎ
YF
2026-06-15 04:01:29
(2 weeks ago)
Attaque distribuรฉe subnet
DDoS Attack
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-14 22:19:28
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
๐ง๐พ
lns.bz
2026-06-14 16:22:27
(2 weeks ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 10:18:13
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.249.171 (171.249.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.249.171 (171.249.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:18:09.979593 2026] [security2:error] [pid 1671:tid 1671] [client 34.101.249.171:54080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leviwalkerportfolio.com"] [uri "/.env.development"] [unique_id "ai5_4cWQMCH7Kh4rlbqeewAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-14 10:10:54
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-06-14 07:09:53
(2 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฉ๐ช
todix
2026-06-14 05:30:25
(2 weeks ago)
WebAttack or semilar from 34.101.249.171
Web App Attack
๐บ๐ธ
mnsf
2026-06-14 05:08:30
(2 weeks ago)
Too many Status 40X (31)
Scanning/Probing (31)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 04:15:04
(2 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-14 02:15:08
(2 weeks ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot